Vulnerabilities > Torproject > TOR > High

DATE CVE VULNERABILITY TITLE RISK
2022-07-17 CVE-2022-33903 Unspecified vulnerability in Torproject TOR
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
network
low complexity
torproject
7.5
2021-08-30 CVE-2021-38385 Reachable Assertion vulnerability in Torproject TOR
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
network
low complexity
torproject CWE-617
7.5
2021-06-29 CVE-2021-34548 Authentication Bypass by Spoofing vulnerability in Torproject TOR
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003.
network
low complexity
torproject CWE-290
7.5
2021-03-19 CVE-2021-28089 Resource Exhaustion vulnerability in multiple products
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
network
low complexity
torproject fedoraproject CWE-400
7.5
2020-03-23 CVE-2020-10593 Memory Leak vulnerability in multiple products
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004.
network
low complexity
torproject opensuse CWE-401
7.5
2020-03-23 CVE-2020-10592 Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
network
low complexity
torproject opensuse
7.8
2017-12-05 CVE-2016-1254 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
7.5